Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

URL Filtering on ASA 5520?

Hi, I am currently filtering users web sites internally via a product called Surf Control (now owed my Websense). The thing is I have now configured the ASA to accept VPN connections from users. They can get access to the internet but it is not monitored. Currently the inside port of the ASA plugs into a Cisco 3750 vlan switch where there is a surfcontrol server too and port mirroring. I think the VPN users bypass this and go through the outside interface instead so they are not filtered.

What do other network guys do to block websites?

thanks

5 REPLIES
Gold

Re: URL Filtering on ASA 5520?

so the URL filtering works normally as it should for local LAN users. It's just for remote access vpn users that it's not working for?

New Member

Re: URL Filtering on ASA 5520?

Yeah that's right

New Member

Re: URL Filtering on ASA 5520?

Any more anwers on this? I am having the same issue.

New Member

Re: URL Filtering on ASA 5520?

Yup, I think vpn users redirect from the outside interface to the internet.

New Member

Re: URL Filtering on ASA 5520?

Hi there

First of all, you need to make sure your users are using the proxy in there settings.

Then, all you need to do is a static nat from your proxy server to a public address from your pool. Then create a rule just to allow ftp,ssl,and http from your proxy server only.

I would also make sure that you have not enabled traffic between 2 or more hosts connected to the same interface, this may be what it is.

cheers

Carl

591
Views
0
Helpful
5
Replies
CreatePlease to create content